Home > General > WINNT\Fonts\explorer.exe


Starting yesterday, the Win2K computer is unable to resolve host or domain names. Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum. It opens TCP port 5800 and 5900 and started listen for VNC requests. Select a target to scan: Click on "My Computer"8. his comment is here

i really don't think i'm jumping to conclusions....norton has detected 3 instances of trojans in the past month on my system. Sign Up so we know who to pay! (It's FREE.) 2. SMAC 1.1 is released on January 25, 2003! If running MSAS beta you may receive an alert that an IE ActiveX program requires your approval.

HiJackThis------------------------------------------------------------------------------- KASPERSKY ON-LINE SCANNER REPORT Friday, May 19, 2006 6:41:39 PM Operating System: Microsoft Windows 2000 Professional, (Build 2195) Kaspersky On-line Scanner version: Kaspersky Anti-Virus database last update: 19/05/2006 Kaspersky A+, Network+, Security+, and MCP certifiedradiosplace.com - kreativekristie.com Back to top #62 Dee Dee Member Members 150 posts Location:Ireland Posted 16 August 2003 - 05:57 PM I have just run this Click here to Register a free account now! My computer is slow---My Blog---Follow me on Twitter.

  • after i noticed that "Update" run initially, I looked in regedit for auto-load programs, saw the call to fonts\explorer.exe, and I did see 2 explorers in Task Manager.
  • i couldn't actually see any non-font files when i used windows explorer to look at the fonts folder.
  • and yes. thanks for your help!
  • My computer is slow---My Blog---Follow me on Twitter.
  • And i can't guarantee you that the damage it already caused can be repairable.
  • In addition, you may want to install another layer of firewall for this subnet for extra protection.
  • Back to top #7 gruden gruden Topic Starter Members 8 posts OFFLINE Local time:05:00 AM Posted 19 May 2006 - 11:32 AM Hi again, I tried to download the Kaspersky
  • Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXEO9 - Extra 'Tools' menuitem: Yahoo!
  • Please re-enable javascript to access full functionality.
  • Knightfal Senior Member posted: Feb. 7, 2003 @ 1:02p Norton probably wont catch it because its not a virus or a trojan.

haven't seen it after i deleted those darn files and removed the call from regedit. etaf replied Mar 18, 2017 at 4:08 AM mkv files ali3500 replied Mar 18, 2017 at 3:41 AM Dual Boot XP & 7 mopargary19355 replied Mar 18, 2017 at 3:17 AM Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.Press OK to remove them.* Restore your websettings: Go to start > controlpanel > Internetoptions > Tab I know that W2K does not have that utility.

If you're not already familiar with forums, watch our Welcome Guide to get started. Use your arrow keys to move to "Safe Mode" and press your Enter key.* Start HijackThis, close all open windows leaving only HijackThis running. Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXEO9 - Extra button: ComcastHSI - {3912CA90-A388-4B76-9E36-E5877BFE9201} - http://www.comcast.net (file missing) (HKCU)O9 - Extra button: Help - {52DE5D47-D1BB-4544-BDCD-96B0BB7E04FA} - http://www.comcast.net/memberservices/ (file missing) (HKCU)O9 - Extra button: Support Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - Global Startup: AUTOCHK.LNK = C:\CFGSAFE\AUTOCHK.EXE O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem:

If you don't have one, I recommend swat-it by Lockdowncorp.com, a FREE Trojan Scanner. This is a more powerful version of "NetStat." A. Back to top #93 radio radio Gator skins 4sale Anti-Spyware Brigade 12,748 posts Gender:Male Location:CT Posted 17 August 2003 - 08:37 PM YOU GUYS KILLED THEM ALL OFF. Firewall has just alerted me asking do I wish to allow a fixtool for W32 Blaster.Worm to access - YOUR RIGHT I DON'T AHHH stinger is just completed and it has

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum. http://www.klcconsulting.net/deloder_virus_analysis.htm It's FREE, fun, and addicting. I wanted to post here prior to further action. I deny it access every time, not setting it to permanitly deny so that I can see when it acts up, but while I was playing the game it had access

NSLOOKUP shows a timeout in connecting to the name servers. http://upxpress.net/general/windows-explorer-exe.php only way I could actually see all those nasty .exe's and .vxd's was to do a find for *.* within c:\winnt\fonts. 1 comment and 2 questions:comment: I have norton running on I don't offer a cleaning service but try to point to possibilitie at times.My question is why so much in that log and why did you have these services running?Bob Flag If you see rundll32.exe running, a.

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum. Edit: Ack, not again! Thanks. weblink What does this mean?

Install an Anti-Trojan software and make sure you scan your systems regularly. v Back to top « Prev Page 4 of 5 2 3 4 5 Next Back to Viruses, Spyware, Adware 0 user(s) are reading this topic 0 members, 0 guests, 0 As always, only allow necessary ports to open and explicit deny all other traffics. 6.

Retehi, Mar 5, 2003 #1 Sponsor TonyKlein Malware Specialist Joined: Aug 26, 2001 Messages: 10,392 Well, it's a baddie for sure, probably a backdoor trojan.

Any help would be apprieciated. Log in or Sign up Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > Computer problem? AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! Messenger (HKLM) O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop...p/PCPitStop.CAB O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class)

Edited by Dee, 17 August 2003 - 05:05 PM. Virus/Worm/Trojan Resources Trojan Paper Virus List Trojans Library Trojan Ports Symantec AV Virus Alert Updated 04/22/2003 DeLoder Worm/Trojan Analysis (DeLoder-A) URL of this article: http://www.klcconsulting.net/deloder_worm.htm version 1.4 --- (Initial Release My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here! check over here FatWallet is not responsible for the content, accuracy, completeness or validity of any information contained in any attached file.

We may have boken the record for scans on one machine?? Is the e-mail with SOPHIE-2.DOC now gone? put a check next to it, O4 - HKLM\..\RunServices: [GLSetIT32] C:\winnt\system32\msiexec16.exe also 'fix' this line, then reboot: O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon after rebooting, delete this file: C:\WINNT\System32\msblast.exe also, You had me worried there for a minute Dee!

[email protected] www.klcconsulting.net ************ The analysis of the follow-up experiment was released on 3/27/2003. Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - Global Startup: AUTOCHK.LNK = C:\CFGSAFE\AUTOCHK.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE Is it possible the spyware/malware disabled the anti-virus?Here (below) are the 3 scan/logs as instructed: 1.Kaspersky Scan (27 Viruses, 52 infected objects)2. it shouldn't start up again after rebooting now anyway.

WINNT\Fonts\explorer.exe Discussion in 'Virus & Other Malware Removal' started by Retehi, Mar 5, 2003. Yankees Senior Member - 3K posted: Feb. 7, 2003 @ 7:46p yes.